Network security for encrypted channel based on reputation
US-2016373433-A1 · Dec 22, 2016 · US
US9838355B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9838355-B1 |
| Application number | US-201615276072-A |
| Country | US |
| Kind code | B1 |
| Filing date | Sep 26, 2016 |
| Priority date | Sep 30, 2014 |
| Publication date | Dec 5, 2017 |
| Grant date | Dec 5, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method includes receiving a first analytics set performed on a first network security appliance operated internal to a first organization, receiving a second analytics set performed on a second network security appliance operated internal to a second organization, processing the first analytics set and the second analytics set, and responsive to the processing, disseminating to the second network security appliance information indicating that the second analytics set has also been performed on at least the first network security appliance, without revealing an identity of the first organization. In one embodiment at least part of the first analytics set or the second analytics set is hashed.
Opening claim text (preview).
What is claimed is: 1. A method comprising: receiving, at a central server from a first network security appliance, a first analytics set performed on the first network security appliance operated internal to a first organization; processing, at the central server, the first analytics set to obtain a recommended subsequent analytics selection; receiving, at the central server from a second network security appliance, an initial analytics selection associated with a second analytics set performed on the second network security appliance operated internal to a second organization; responsive to receiving the initial analytics selection, disseminating from the central server to the second network security appliance the recommended subsequent analytics selection, without revealing an identity of the first organization; wherein at least a portion of the first analytics set is organized in a search tree, the search tree comprising a lead value and an audit trail, the lead value representing a user token and a time, the user token being associated with one or more network administrators of the first organization performing one or more actions in the audit trail, the time being associated with performance of the one or more actions in the audit trail; and wherein the recommended subsequent analytics selection is based at least in part on: (i) a reputation of the one or more network administrators associated with the user token; and (ii) the time associated with performance of the one or more actions in the audit trail. 2. The method of claim 1 , wherein at least part of the first analytics set or the initial analytics selections is hashed. 3. The method of claim 1 , wherein the first analytics set comprises an indication of activity of at least one network administrator responsible for network security for the first organization. 4. The method of claim 1 , wherein disseminating to the second network security appliance the recommended subsequent analytics selection, without revealing an identity of the first organization comprises sending an alert to the second network security appliance. 5. The method of claim 4 , further comprising receiving a message from the second network security appliance in response to the alert. 6. The method of claim 1 , wherein the first analytics set and the initial analytics selection indicate at least one of an order in which the one or more network administrators performed individual operations of the first analytics set or the initial analytics selection, or a velocity at which the one or more network administrators performed individual operations of the first analytics set or the initial analytics selection. 7. The method of claim 1 , further comprising creating a recommendation for network administrators other than network administrators of the first organization and the second organization, the recommendation being based on the first analytics set or the initial analytics selection. 8. The method of claim 7 , wherein creating the recommendation is based on a reputation of the one or more network administrators who generated the first analytics set or the initial analytics selection. 9. The method of claim 1 , further comprising organizing the initial analytics selection in another search tree. 10. The method of claim 1 , wherein the search tree comprises a Merkle tree. 11. An apparatus configured to share security analytics among a plurality of security network appliances deployed in respective network domains, the apparatus comprising: a processor; a network interface configured to receive a first analytics set and an initial analytics selection associated with a second analytics set from, respectively, a first network domain and a second network domain; and a memory, storing logic instructions, which, when executed by the processor, are configured to: process the first analytics set to obtain a recommended subsequent analytics selection; and in response to receiving the initial analytics selection, disseminate to the second network domain the recommended subsequent analytics selection, without revealing an identity of the first network domain; wherein at least a portion of the first analytics set is organized in a search tree, the search tree comprising a lead value and an audit trail, the lead value representing a user token and a time, the user token being associated with one or more network administrators of the first organization performing one or more actions in the audit trail, the time being associated with performance of the one or more actions in the audit trail; and wherein the recommended subsequent analytics selection is based at least in part on: (i) a reputation of the one or more network administrators associated with the user token; and (ii) the time associated with performance of the one or more actions in the audit trail. 12. The apparatus of claim 11 , wherein at least part of the first analytics set or the initial analytics selection is hashed. 13. The apparatus of claim 11 , wherein the first analytics set comprises an indication of activity of at least one network administrator responsible for network security for the first network domain. 14. The apparatus of claim 11 , wherein the logic instructions, which, when executed by the processor, are further configured to send an alert to the second network domain. 15. The apparatus of claim 14 , wherein the logic instructions, which, when executed by the processor, are further configured to receive a message from the second network domain in response to the alert. 16. The apparatus of claim 11 , wherein the first analytics set and the initial analytics selection comprise at least one of an order in which the one or more network administrators performed security analytics, or a velocity at which the one or more network administrators performed security analytics. 17. The apparatus of claim 11 , wherein the logic instructions, which, when executed by the processor, are further configured to create a recommendation to network administrators other than network administrators of the first organization and the second organization, the recommendation being based on the first analytics set or the initial analytics selection. 18. A computer program product comprising a non-transitory computer-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device: to receive, from a first network security appliance, a first analytics set performed on the first network security appliance operated internal to a first organization; to process the first analytics set to obtain a recommended subsequent analytics selection; to receive, from a second network security appliance, an initial analytics selection associated with a second analytics set performed on the second network security appliance operated internal to a second organization; responsive to receiving the initial analytics selection, to disseminate to the second network security appliance the recommended subsequent analytics selection, without revealing an identity of the first organization; wherein at least a portion of the first analytics set is organized in a search tree, the search tree comprising a lead value and an audit trail, the lead value representing a user token and a time, the user token being associated with one or more network administrators of the first organization performing one or more actions in the audit trail, the time being associated with performance
Vulnerability analysis · CPC title
Network analysis or design · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
for separating internal from external traffic, e.g. firewalls · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.